class DocumentsController < ApplicationController
  before_filter :authorize
  def show
    @document = Document.find(params[:id])
    send_data(@document.data,
              :filename => @document.name,
              :type => @document.content_type,
              :disposition => "inline")
  end
end
